CVE-2026-11643
Google · Chrome
A Use-After-Free vulnerability in the Google Chrome Proxy component allows for potential memory corruption.
Executive summary
A high-severity Use-After-Free vulnerability in the Google Chrome Proxy component could lead to arbitrary code execution, requiring urgent patching.
Vulnerability
This vulnerability is a Use-After-Free in the Proxy component of the browser. An attacker may exploit this by luring a user to a malicious webpage, triggering a memory corruption event that could lead to unauthorized code execution.
Business impact
The CVSS score of 8.1 reflects the high risk of this vulnerability. Successful exploitation could result in full compromise of the user session, potentially leading to the loss of sensitive data, credentials, and persistent access to the local workstation.
Remediation
Immediate Action: Update all instances of Google Chrome to version 149.0.7827.53/54 (Windows/Mac) or 149.0.7827.53 (Linux) without delay.
Proactive Monitoring: Review browser logs for signs of unexpected termination or memory access violations.
Compensating Controls: Deploy host-based security solutions that monitor for abnormal memory allocation patterns or unauthorized child process spawning by the browser.
Exploitation status
Public Exploit Available: false
Analyst recommendation
This Use-After-Free vulnerability represents a significant risk to browser security. Administrators should expedite the deployment of the Chrome 149 update across the enterprise to mitigate the risk of memory-based attacks.